Known vulnerabilities in the Nextgen Gallery plugin
16 security advisories have been published for the Nextgen Gallery plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- NextGEN Gallery - Cross-Site Scripting (XSS) (CVE-2026-28141) HIGH
- Nextgen Gallery - Security Vulnerability (CVE-2026-6566) MEDIUM
- Nextgen Gallery - Path Traversal (CVE-2026-1463) HIGH
- Nextgen Gallery - Remote Code Execution (CVE-2025-13641) HIGH
- Nextgen Gallery - Cross-Site Scripting (XSS) (CVE-2025-2537) MEDIUM
- Nextgen Gallery - Cross-Site Scripting (XSS) (CVE-2024-5878) MEDIUM
- Nextgen Gallery - Cross-Site Scripting (XSS) (CVE-2024-10545) LOW
- Nextgen Gallery - Cross-Site Scripting (XSS) (CVE-2024-6393) MEDIUM
- Nextgen Gallery - Cross-Site Scripting (XSS) (CVE-2024-5442) MEDIUM
- Nextgen Gallery - Cross-Site Scripting (XSS) (CVE-2024-2744) MEDIUM
- Nextgen Gallery - Broken Access Control (CVE-2024-3097) MEDIUM
- Nextgen Gallery - Cross-Site Request Forgery (CSRF) (CVE-2023-48328) MEDIUM
- Nextgen Gallery - PHP Object Injection (CVE-2023-3154) HIGH
- Nextgen Gallery - Security Vulnerability (CVE-2023-3155) HIGH
- Nextgen Gallery - Improper Input Validation (CVE-2023-3279) MEDIUM
- Nextgen Gallery - Security Vulnerability (CVE-2021-24293) MEDIUM